- Runs periodic scans across all managed endpoints to audit EDR agent configuration
- Detects specific misconfigurations - disabled real-time protection, tamper protection turned off, outdated agent versions, broken sensor connectivity, or overly broad exclusions
- Marks each finding as NEW or existing based on entity tracking, so repeat issues aren't re-flagged
- Notifies the device owner and security team with the specific misconfiguration detected
- Creates a ticket with the misconfiguration details and recommended fix for IT remediation
- Auto-resolves the ticket once the endpoint's configuration is verified back in a secure state
What EDR Misconfiguration Detection does
EDR Misconfiguration Detection audits the endpoint protection you already paid for. On a recurring schedule it checks every managed endpoint for the specific ways EDR quietly stops working: real-time protection switched off, tamper protection disabled, an agent left on an old version, a sensor that stopped reporting, or exclusions drawn so broadly they hollow out coverage. Each finding is marked new or already known, the device owner and the security team are told exactly what is wrong, and a ticket carries the misconfiguration and a recommended fix until the endpoint is verified back in a secure state.
Who EDR Misconfiguration Detection is for
Security operations and endpoint teams who are accountable for EDR coverage across the fleet, not just EDR licensing.
An installed EDR agent looks like coverage on a dashboard. In practice protections get toggled off during troubleshooting, agents fall behind on versions, sensors stop reporting, and exclusions added for one noisy application never come back out. None of it triggers an alert, because from the console the endpoint is still enrolled. The blind spot is only discovered when something gets through it.
How EDR Misconfiguration Detection works
A recurring schedule, configurable per tenant.
- Audit endpoint configuration
Sweeps every managed endpoint and reads the actual configuration state of its EDR agent.
- Detect specific misconfigurations
Looks for disabled real-time protection, tamper protection turned off, outdated agent versions, broken sensor connectivity, and overly broad exclusions.
- Mark new versus existing findings
Uses entity tracking to separate the first sighting of an issue from one already being worked, so repeat issues aren't re-flagged every run.
- Notify owner and security team
Tells the device owner and the security team which specific misconfiguration was detected, not just that something is wrong.
- Create a remediation ticket
Opens a ticket carrying the misconfiguration details and the recommended fix for IT to action.
- Auto-resolve on verification
Closes the ticket once the endpoint's configuration is verified back in a secure state.
Every endpoint whose protection has drifted has a named misconfiguration, an owner, and a ticket with a recommended fix, closed automatically once the endpoint checks out clean.
Capabilities
- Scheduled configuration audits - Sweeps the managed fleet on a recurring schedule rather than waiting for an incident.
- Named misconfiguration detection - Flags disabled real-time protection, tamper protection off, outdated agent versions, broken sensor connectivity, and overly broad exclusions as distinct findings.
- New versus existing tracking - Marks each finding NEW or existing, so the same issue isn't re-reported while it's being fixed.
- Specific, actionable notifications - Both the device owner and the security team are told which misconfiguration was found.
- Tickets with a recommended fix - Each ticket carries the detail and the remediation step, so IT is not starting from a bare alert.
- Verified automatic closure - The ticket resolves only once the configuration is confirmed back in a secure state.
Main use cases
Protection switched off and never switched back - Real-time protection gets disabled to unblock a build, and nobody re-enables it. The next audit names the exact setting, tells the owner and the security team, and tickets it - the endpoint doesn't spend a quarter unprotected while looking enrolled.
Exclusions that hollow out coverage - An exclusion added for one noisy application is broad enough to cover a whole directory. The agent flags it as a misconfiguration rather than leaving it to be discovered during an incident review.
Sensors that stopped reporting - A sensor breaks connectivity and stops sending telemetry, so the endpoint looks quiet rather than dark. The audit catches the reporting gap and raises it with the owner.
Integrations
| Integration | Role in the agent flow |
|---|---|
| CrowdStrike | EDR agent configuration, version, and sensor health for enrolled endpoints |
| SentinelOne | EDR agent configuration, protection settings, and reporting state |
| Palo Alto Cortex | Endpoint protection posture and policy configuration |
| Microsoft Entra ID | Resolves the employee who owns each flagged device |
| Harmony Service Desk | Native ticketing - creates the ticket, tracks it, and records the outcome |
| Harmony Notifications | Delivers updates through each recipient's preferred channel: Slack, Teams, or email |
FAQ
The console shows enrollment and alerts. This agent audits configuration: whether protections are actually on, whether the agent is current, whether the sensor is reporting, and whether exclusions have grown too broad. An endpoint can look healthy in the console and still fail all four.
Meet more Agents